• ISA provides technical resources and standards to help industrial automation professionals advance their careers and the field. We enable automation professionals worldwide to solve problems and enhance their skills by bringing people together to create new technologies and share best practices with future automation professionals.
    • Industry Insights

  • We attract over 140,000 unique automation professionals monthly, making us the premier online content provider and the only dedicated electronic magazine in the automation industry.

    Monthly Magazine

    • More things to read

    Back
    Back
  • M logo for Automation.com Monthly. Link to current issue.

Beckhoff Meets Growing Security Requirements Driven by Cyber Resilience Act and Machinery Regulation

Source: Beckhoff Automation
20 July, 2026
3 min read
Feature Image for Beckhoff Meets Growing Security Requirements Driven by Cyber Resilience Act and Machinery Regulation
Beckhoff is actively driving standard development to bring automation technology in line with the new EU regulations.

SAVAGE, Minnesota, May 20, 2026 — The risks facing the manufacturing industry from cyberattacks and malware are constantly growing. Regulations in Europe such as the Cyber Resilience Act (CRA) and the new Machinery Regulation aim to counter these by imposing stringent requirements on manufacturers and machine builders. With PC-based control and EtherCAT, Beckhoff offers an optimal technological foundation for meeting these requirements and securing a cybersecurity competitive advantage in the future.

The regulatory requirements in industrial manufacturing are undergoing a fundamental shift as the Cyber Resilience Act (EU) 2024/2847 and the revised Machinery Regulation (EU) 2023/1230 have come into force. In the future, cybersecurity will require continuous interplay between technology and processes. Anticipating this need early on, Beckhoff has been operating its own Product Security Incident Response Team (PSIRT) over the last 10 years for professional vulnerability management and has made detailed security guidelines regularly available. As a co-founder of the industry-specific CERT@VDE, Beckhoff is also actively involved in sharing vulnerability information across manufacturers.

Boost cybersecurity with PC-based control and EtherCAT

Beckhoff is actively driving standard development to bring automation technology in line with the new EU regulations. Since the international IEC 62443 series of standards alone does not currently provide a sufficient basis for the CRA, Beckhoff is helping advance the development of the European version, EN IEC 62443, within CEN-CENELEC. The aim is to achieve practical standardization that guarantees effective security.

From a technological standpoint, PC-based control and EtherCAT provide a secure foundation with many key cybersecurity features built-in. By centralizing system communication through the industrial PC, the native security capabilities of the operating systems in use — such as Windows or Linux — can be fully applied to the PLC runtime, including integrated firewalls.

Furthermore, the system architecture benefits significantly from communication via EtherCAT. Even more than 20 years after its introduction, the protocol remains consistently geared toward hardware-based real-time control and is clearly separated from higher-level IP networks, leaving very little room for cyberattacks. As a result, EtherCAT can be used in a cybersecure, standard-compliant manner without any protocol changes. This enables system certifications in accordance with ISA/IEC 62443-3-3 for EtherCAT systems, even if the individual devices are not explicitly certified. Beckhoff has already received UL certifications for three different blueprint scenarios (DK-177530-UL, DK-178394-UL and DK-178399-UL). Each of these are tailored to a typical family of industrial applications – a crucial factor in maintaining existing system designs.

Advertisement

Evaluation and certification

At the product level, Beckhoff relies on a rigorous security evaluation process. All products are continuously assessed and further developed regarding their compliance with the CRA and, where necessary, with IEC 62443. In many cases, they already meet the requirements through their existing design and only require extended documentation. For safety components, full compliance with the new Machinery Regulation will be ensured in time for it to take effect in January 2027. Beckhoff is also expected to complete IEC 62443-4-1 certification this year to safeguard the product development lifecycle. At the same time, the security of the company’s own IT and production infrastructure will soon be validated through ISO 27001 certification.

“Cybersecurity is not static, but is an ongoing process that requires tailored technologies and clear guidance,” summarized Torsten Förder, responsible for Product Compliance Security at Beckhoff. “Where others in the market recommend excessive protective measures, we focus specifically on what is needed to deliver effective security. With this streamlined approach and the Beckhoff portfolio as a technical foundation, users remain secure, protect their investments and maintain their edge.”

UL Solutions certifies EtherCAT's cyber resilience

UL certificates confirm the EtherCAT Technology Group’s assessment and demonstrate that EtherCAT meets ISA/IEC 62443 / CRA requirements for Security Level 2 without modifications.

The report and certificates from UL Solutions, following testing in accordance with IEC 62443, confirm the ETG’s statements: EtherCAT technology already meets the requirements for systems exposed to cyber attacks corresponding to Security Level 2 without any modifications. In its European version IEC 62443, the international standard for cybersecurity of industrial control systems, will also form the basis for the European Cyber Resilience Act. Furthermore, the investigations show that no hardware changes are necessary for higher security requirements—with targeted software enhancements, higher security levels can also be achieved based on the EtherCAT system.

UL mapped all 100+ System Requirements (SR) of IEC 62443-3-3 to three typical EtherCAT systems with different threat scenarios and evaluated the degree of compliance achieved by EtherCAT.

“We at UL Solutions were delighted to work with an industrial protocol which has security capabilities and enablement-by-design as well as hardware implemented security, which is second-to-none in the category of industrial protocols," said Alexander W. Koehler, S&S principal security advisor for Cybersecurity at UL Solutions. “IT and OT-security have not been best friends in the past. IT security requirements have often been driven by typical short product lifecycles of office worker equipment, which contrast with industrial equipment with long lifecycles. In consequence there are still many products in the industrial field without or weak security built in, labelled as legacy products. EtherCAT is a positive exception here.”

Dr. Guido Beckmann, chair of the Technical Committee of the EtherCAT Technology Group: “The results of the extensive investigations confirm the ETG’s assessment: EtherCAT already provides a high level of cyber security protection for industrial applications today. The tested and documented features and measures form the basis for the recommendations and specifications we are developing for manufacturers and users of EtherCAT devices.”

Advertisement

Trending Articles

Advertisement

Related Articles

View all Articles and News
Advertisement
Advertisement